Webhooks

Rotate the signing secret

POST
/v1/webhook-endpoints/{id}/rotate-secret

Creates a new secret, shown only in this response. While the overlap lasts, each delivery carries two signatures, one per secret, so you can switch yours without missing any.

Authorization

AuthorizationBearer <token>

Your API key, which acts for the one business it was created for: fb_sandbox_… issues in sandbox, fb_test_… in test, the tax authority's testing service, and fb_live_… in live.

In: header

Path Parameters

id*string
Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

expires_in_hours?integer

How many hours the previous secret keeps signing alongside the new one, from 0 to 72. With 0 it stops being valid immediately: use it if it leaked.

Range0 <= value <= 72
Default24

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/v1/webhook-endpoints/497f6eca-6276-4993-bfeb-53cbbbba6f08/rotate-secret" \  -H "Content-Type: application/json" \  -d '{}'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "object": "webhook_endpoint",  "environment": "sandbox",  "url": "http://example.com",  "events": [    "*"  ],  "disabled": true,  "secret_hint": "string",  "previous_secret_expires_at": "2019-08-24T14:15:22Z",  "deliveries_24h": 0,  "failed_24h": 0,  "failing_since": "2019-08-24T14:15:22Z",  "created_at": "2019-08-24T14:15:22Z",  "secret": "string"}